A newly reported WhatsApp Android vulnerability can expose photos on some locked Android phones during an incoming video call. The issue requires physical access and appears to depend on the phone maker’s handling of lock-screen permissions. More than 3.3 billion people use the same green app worldwide, assuming they have secured it properly. Latest research suggests otherwise.
- A lock screen bypass exposed galleries on some Pixel and Oppo handsets without a PIN.
- Google’s Project Zero disclosed a separate zero-click group media flaw, now patched.
- Group chats still lack cryptographic membership control, a gap first flagged in 2017.
- The big 2026 WhatsApp malware waves hit Windows, not Android phones.
- Britain’s NCSC has issued fresh advice for people at higher risk.
Lock Screen Photo Bypass During Video Calls
This one needs no coding skill. Independent researcher Jose Rodriguez published it on X on 1 September 2026, calling it “hidden in plain sight”. A locked Android phone receives a video call. Whoever holds it swipes to answer, which is normal. They then tap the effects icon, switch to backgrounds, choose Select “Create with Meta AI”, and then choose the edit photo option. The media picker opens, and the full gallery appears. No PIN. No fingerprint. Testing by NotebookCheck found the path worked on a Pixel 6 Pro running Android 17 and an Oppo K13 on ColorOS 16.
A Samsung Galaxy S25 Ultra on One UI 8.5 blocked it and demanded authentication. Risk depends on how each manufacturer handles lock screen boundaries. Heise reported that the bypass only reveals photos. It does not unlock the device, and images cannot be forwarded or edited. A snooper could still photograph the screen. iPhones are immune. Apple’s CallKit framework forces WhatsApp to use the native iOS call screen, so the custom effects menu never appears. Status: Meta began rolling out a fix on 3 September 2026, calling it a rare scenario needing physical access.
Also Read: Apple Watch Ultra 4: Price, Features, Battery Life and What’s New in 2026
Zero-Click Media Delivery in Group Chats
Google Project Zero researcher Brendon Tiszka reported a very different problem to Meta on 1 September 2025. It went public on 26 January 2026 after the standard 90-day deadline lapsed. An attacker creates a group, adds the target plus one of their real contacts, then often promotes that contact to admin so it looks genuine. A crafted media file follows.
With auto-download on, the phone fetches and processes it without a tap. Wizard Cyber states that WhatsApp acts as a trusted transport layer. This is not remote code execution by itself. The danger is an attacker-chosen file landing in storage, where Android’s media stack or gallery apps may parse it. Affected builds were 2.25.22.80 and 2.25.23.81. A partial server-side mitigation arrived in late 2025. Project Zero pushed back, and Meta shipped a comprehensive fix by late January 2026.
Group Chats Without Cryptographic Membership Control
Researchers at King’s College London, Martin R. Albrecht and Benjamin Dowling, with Royal Holloway PhD student Daniel Jones, reverse-engineered the app. Their EuroCrypt 2025 paper was a world first. The good news is that they proved the end-to-end encryption holds up, so Meta cannot read your messages. The problem sits with groups. Membership changes are handled by the server, not by cryptography, and are not limited to existing members.
Anyone controlling those servers could slip a silent observer into a chat. Albrecht warned that responsibility for securing group chats falls on users, not the platform, which is unworkable for groups with hundreds of members. Telegram and Matrix share the weakness. Signal does not.
Also Read: From Me, Natalie to Dead Man’s Wire: Al Pacino’s Net Worth
List of WhatsApp Android Flaws
| Vulnerability | Year | Risk | Fixed? |
| Lock screen photo bypass | 2026 | Gallery viewed on locked phone | Fix rolling out |
| Zero-click group media | 2025–26 | Hostile file placed on device | Yes, Jan 2026 |
| No membership integrity | 2017–25 | Silent additions to group chats | No, design level |
| CVE-2022-36934 | 2022 | Code execution in a live video call | Yes |
| CVE-2019-11932 | 2019 | Malicious GIF triggered remote code execution | Yes, v2.19.244 |
That 2019 GIF bug sat in an open-source library, not WhatsApp’s own code, and fired when the gallery was opened.
The Malware Campaigns That Are Not Android Bugs
Microsoft Defender Experts tracked a campaign from late February 2026 spreading Visual Basic Script files through WhatsApp messages. It renamed Windows tools, pulled payloads from cloud hosts such as AWS, weakened User Account Control, then installed unsigned MSI packages. Kaspersky’s GReAT team documented a similar wave in June 2026, with the UK among affected countries and 80% of victims in Malaysia.
Hijacked accounts sent files named like invoices and bank statements. Both target WhatsApp Desktop and Web on Windows. Neither exploits a hole in the Android app. WhatsApp is simply the postbox.
What UK Users Should Do Now
The NCSC warned in March 2026 about Russia-based actors targeting messaging apps, adding a protection infographic in July. Update WhatsApp through the Play Store. Open Settings, Apps, WhatsApp, and Permissions, then set photos and videos to limited access. Turn off media auto-download in Storage and Data. Switch on two-step verification and passkeys. Check linked devices, review group members, and remove anyone you cannot verify. Convenience keeps winning out over caution in app design. Your lock screen is only as strong as the shortcuts on top of it.
FAQs
Is WhatsApp safe on Android in 2026?
Ans: Yes, as message encryption remains intact. Recent issues involved photo access and file delivery, not broken encryption. Updating the app closes most of the gap.
What is the WhatsApp Android vulnerability?
Ans: It is a lock screen bypass found on 1 September 2026. Answering a video call on a locked phone opens a route into the gallery via the Meta AI background tool.
Has WhatsApp fixed the photo bug?
Ans: Meta confirmed a fix began rolling out on 3 September 2026. Update through the Play Store, as staged rollouts reach handsets at different times.
Can someone read my WhatsApp remotely?
Ans: No, these flaws are patched. The photo bug needs physical access, and the group media bug was resolved in January 2026.
How do I stop WhatsApp seeing all my photos?
Ans: Open Settings, then Apps, then WhatsApp, then Permissions, then Photos and Videos. Choose limited access and select only the images the app may access.
Are iPhones affected by this flaw?
Ans: No. Apple’s CallKit framework forces incoming calls onto the native iOS screen, so the effects menu enabling the bypass never loads.
Sources & References:
- KCL – Researchers at King’s College London proved that the end-to-end encryption holds up, so Meta cannot read your messages.
- Microsoft – Tracked a campaign from late February 2026 spreading Visual Basic Script files through WhatsApp messages.
- Heise – The bypass only reveals photos.
- Wizard Cyber – WhatsApp serves as a trusted transport layer.
Leave a Reply